Cisco Systems PIX515E quick start

Page 19

d.Enter the Source Host/Network information (0.0.0.0 for any host or network).

e.Under Destination Host/Network, click the IP Address radio button.

f.Select dmz from the Interface drop-down menu.

g.Enter 30.30.30.30 in the IP address box.

h.Select 255.255.255.255 from the Mask drop-down menu.

Note Alternatively, you can select the Hosts/Networks in both cases by clicking on the respective Browse buttons.

Select the type of traffic that you would permit:

Note HTTP traffic is always directed from any TCP source port number toward a fixed destination TCP port number 80.

i.Select the TCP radio button, under Protocol and Service.

j.Select “=” (equal to) from the Service drop-down menu under Source Port.

k.Scroll through the options, and select Any.

l.Select “=” (equal to) from the Service drop-down menu under Destination Port.

m.Scroll through the options, and select HTTP.

n.Click the OK button.

Note For additional features, such as system log messages by ACL, check the radio button at the top and click the More options button. You can provide a name for the access rule in the window at the bottom.

o.Check the various fields for accuracy and click the OK button.

Note Although the destination address specified above is the private address of the DMZ web server (30.30.30.30), HTTP traffic from any host on the Internet destined for 209.165.156.11 is permitted through the PIX 515E. This is made possible by the translation (30.30.30.30 = 209.165.156.11).

p.Click the Apply button in the main window.

19

Image 19
Contents Cisco PIX 515E Firewall Software Features Hardware FeaturesAbout the Cisco PIX 515E Firewall Check Items Included 69-0123-01 69-0124-01 69-0125-01 Power cable Rubber feetDMZ Install the PIX 515EConfigure the PIX 515E DMZ Configuration Example ConfigurationsManage IP Pools for Network Translations Select the Translation Rules tab Page Page Configure Address Translations on Private Networks Page Page Page Configure External Identity for the DMZ Web Server Configurations should display as shown below Provide Http Access to the DMZ Web Server Page Page Site-to-Site VPN Configuration Start the VPN Wizard Configure the VPN Peer Page Configure the IKE Policy Page Configure Internal Traffic Page View and Enable VPN Commands Establishing Site-to-Site VPNs with other Cisco Products Optional Maintenance and Upgrade ProceduresObtaining DES and 3DES/AES Encryption Licenses Command Description Restore the Default ConfigurationHttp 192.168.1.0 Alternative Ways to Access the PIX 515E Ethernet LED Check the LEDsColor Status Description Ordering Documentation Obtaining DocumentationCisco.com Documentation CD-ROMObtaining Technical Assistance Documentation FeedbackCisco TAC Website TAC Case Priority Definitions Opening a TAC CaseObtaining Additional Publications and Information Page USA